CVE-2021-23567 describes a Denial of Service (DoS) vulnerability in the colors.js package versions after 1.4.0, stemming from an intentional infinite loop introduced by a maintainer. This vulnerability carries a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, leading to a complete loss of availability for affected systems. While there are no known public exploits or Metasploit modules, the incident garnered significant community discussion and media coverage due to its unusual nature as a purposeful sabotage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.1CPE matchmatch criteria | cpe:2.3:a:colors.js_project:colors.js:1.4.1:*:*:*:*:node.js:*:* | ||
1.4.44-liberty-2CPE matchmatch criteria | cpe:2.3:a:colors.js_project:colors.js:1.4.44-liberty-2:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.